提出一种基于阈下信道的两方口令认证密钥交换协议。协议中,服务器存储用户口令的验证值抵御服务器泄漏伪装攻击,用户的口令明文采用阈下信道生成签名信息传送给服务器,服务器计算出用户的口令明文恢复出阈下信息,再计算口令验证值以实现对用户身份的认证,从而建立起会话密钥。对所提协议的安全性和效率进行分析,结果表明:所提出的协议安全可行且有效。
A two-party password-authenticated key exchange protocol based on the subliminal channel was proposed.In the proposed protocol,the server stores the user′s password verifier to withstand the server′s compromise and guise attacks,the user′s password cleartext is made to a signature message with the subliminal channel to transmit to the server, the server computes the user′s password cleartext to renew the subliminal message,then the server calculates the pass-word verifier to authenticate the user′s identity,so a session key is made between the server and the user.The security and the efficiency of the proposed protocol were analyzed,it shows in the analysis that the proposed protocol is secure and effective.